Skip to content
SecArsenal
Educational and ethical use only. Only test systems you own or are explicitly authorized to test. Full disclaimer.

rubilyn

64bit Mac OS-X kernel rootkit that uses no hardcoded address to hook the BSD subsystem in all OS-X Lion & below. It uses

backdoorRed Team
Official docs ↗Download ↗

Platforms: Linux · Last verified September 6, 2026

64bit Mac OS-X kernel rootkit that uses no hardcoded address to hook the BSD subsystem in all OS-X Lion & below. It uses a combination of syscall hooking and DKOM to hide activity on a host.

Only use this tool against systems you own or are explicitly authorized to test — see the disclaimer.

Getting started

Install on BlackArch with `pacman -S rubilyn` (or add the BlackArch repository to an existing Arch Linux install). See the official BlackArch tool listing and upstream homepage linked above for details.

Commonly preinstalled on

BlackArch

Arch Linux-based distribution with one of the largest pentest tool repositories